Hunting MacSync Stealer Infrastructure Through Behavioral Pivots
Microsoft, Tuesday, August 18th, 2026
Microsoft uncovered 30+ MacSync Stealer domains using durable behavioral pivots despite rapid domain rotation.
Microsoft published threat hunting research on MacSync Stealer, which rapidly rotates domains to evade detection. Although the infrastructure changes constantly, the malware's behavior stays consistent, which gives defenders something durable to pivot on. Microsoft used those behavioral pivots to uncover more than 30 related domains.
The post explains which characteristics remained stable across rotations and why they work as hunting anchors. It is written as a methodology piece defenders can apply to other fast-rotating infrastructure.